2. Create the necessary http traffic to cause an incident. 3. Verify an incident is created. 4. From the Enforce UI stop the File Reader on the network monitor. 5. Create the necessary HTTP traffic again. 6. Wait for a file of type .vpcap to appear in the drop_pcap folder or sub-folder. 7. Copy the new file to a safe place. 8. From the Enforce UI start the File Reader on the network monitor 9. Verify a new incident is created.

The copied .vpcap can be used to create new incidents without having to create the HTTP traffic. Copy the file and then paste it into the \drop_pcap file.

NOTE: In Windows the .vpcap file can not be dragged and dropped into the \drop_pcap folder. Windows does not see this as creating a new file and the File Reader will not see the file and will not create a new incident.

Imported Document ID: TECH219759

Legacy ID:
42575

Subscribing will provide email updates when this Article is updated. Login is required.